Cybersecurity SOC Analyst / Incident Responder for 30–45 Min Research Interview
Budget / SalaryHourly project
TypeFreelance project
LocationRemote
Posted1 hour ago
I’m researching how security teams investigate alerts and understand the current security state of their environment. I’m looking to speak with experienced cybersecurity practitioners for a paid 30–45 minute interview.
This is not a technical implementation project and there is no preparation required. I’m primarily interested in understanding your real day-to-day workflow: what happens after an alert arrives, what tools you use, what information is missing, what repetitive work takes the most time, and where existing SIEM, EDR, XDR, or AI SOC products fall short.
During the call, I’d like to discuss a recent or representative investigation and walk through questions such as: What did the initial alert tell you? What did you need to investigate next? Which tools or data sources did you check? How did you determine whether the activity was benign or malicious? How do you understand whether one host, user, or credential is related to a larger incident? What causes alert fatigue? How much manual enrichment or context gathering do you do? How are detection rules tuned for your organization? What do you wish your existing tools understood automatically?
I’m especially interested in the gap between individual alerts and understanding the broader state of the environment, such as which machines may actually be compromised, how confident the team is, what evidence supports that conclusion, and how that understanding changes as new events arrive.
Ideal candidates have hands-on experience in a SOC, MDR/MSSP, incident response, detection engineering, security operations, or blue-team role. Experience with tools such as Splunk, Microsoft Sentinel, QRadar, CrowdStrike, SentinelOne, Microsoft Defender, Okta, or similar platforms is helpful, but no specific vendor experience is required.
I am particularly interested in speaking with people who have personally investigated alerts rather than only managed cybersecurity teams at a high level. Experience with AI SOC or security automation products is a bonus.
Please include a short description of your current or previous security role, approximately how many years of hands-on experience you have, whether you have worked in an internal SOC or MSSP/MDR environment, and the security tools you regularly use. You must be able to communicate fluently in English during a live video call. If requested, you should be comfortable walking me through your typical investigation workflow during the call, for example by screen sharing a demo, test environment, sanitized screenshots, or a mock case. Do not share any confidential client, employer, customer, or sensitive production data.
This is not a technical implementation project and there is no preparation required. I’m primarily interested in understanding your real day-to-day workflow: what happens after an alert arrives, what tools you use, what information is missing, what repetitive work takes the most time, and where existing SIEM, EDR, XDR, or AI SOC products fall short.
During the call, I’d like to discuss a recent or representative investigation and walk through questions such as: What did the initial alert tell you? What did you need to investigate next? Which tools or data sources did you check? How did you determine whether the activity was benign or malicious? How do you understand whether one host, user, or credential is related to a larger incident? What causes alert fatigue? How much manual enrichment or context gathering do you do? How are detection rules tuned for your organization? What do you wish your existing tools understood automatically?
I’m especially interested in the gap between individual alerts and understanding the broader state of the environment, such as which machines may actually be compromised, how confident the team is, what evidence supports that conclusion, and how that understanding changes as new events arrive.
Ideal candidates have hands-on experience in a SOC, MDR/MSSP, incident response, detection engineering, security operations, or blue-team role. Experience with tools such as Splunk, Microsoft Sentinel, QRadar, CrowdStrike, SentinelOne, Microsoft Defender, Okta, or similar platforms is helpful, but no specific vendor experience is required.
I am particularly interested in speaking with people who have personally investigated alerts rather than only managed cybersecurity teams at a high level. Experience with AI SOC or security automation products is a bonus.
Please include a short description of your current or previous security role, approximately how many years of hands-on experience you have, whether you have worked in an internal SOC or MSSP/MDR environment, and the security tools you regularly use. You must be able to communicate fluently in English during a live video call. If requested, you should be comfortable walking me through your typical investigation workflow during the call, for example by screen sharing a demo, test environment, sanitized screenshots, or a mock case. Do not share any confidential client, employer, customer, or sensitive production data.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.